HHS Office for Civil Rights Reaches Settlement with Ambry Genetics Over HIPAA Breach Linked to Phishing Incident Impacting 225,000 Patients
-
By
-
Office for Civil Rights (OCR)
-
September 17, 2026
Clinical Report: HHS Office for Civil Rights Reaches Settlement with Ambry Genetics
Overview
The HHS Office for Civil Rights has reached a settlement with Ambry Genetics over a HIPAA breach linked to a phishing incident affecting 225,370 patients. Ambry will pay $700,000 and implement a corrective action plan to address identified security deficiencies.
Background
The protection of patient health information is critical in healthcare, particularly in light of increasing cyber threats such as phishing attacks. The HIPAA Security Rule establishes essential standards for safeguarding electronic protected health information (ePHI).
Data Highlights
No numerical data or trial data available.
Key Findings
- Ambry Genetics experienced a phishing attack that compromised an employee's email account.
- Protected health information of 225,370 individuals was potentially exfiltrated, including names, addresses, and clinical details.
- OCR identified violations related to risk analysis, termination of access, and user identification procedures.
- Ambry agreed to a two-year corrective action plan and paid a settlement of $700,000.
Clinical Implications
Healthcare organizations must prioritize compliance with HIPAA regulations to protect patient information from cyber threats. Implementing robust risk management strategies and ensuring workforce training are essential steps in safeguarding ePHI.
Conclusion
The settlement with Ambry Genetics serves as a reminder of the ongoing risks associated with cybersecurity in healthcare and the necessity for stringent adherence to HIPAA Security Rule provisions.
Related Resources & Content
- United States Department of Health and Human Services, HHS’ Office for Civil Rights Settles HIPAA Investigation of Ambry Genetics Phishing Attack Affecting 225,000 Individuals, 2026 -- HHS Office for Civil Rights Settles HIPAA Investigation
- United States Department of Health and Human Services, HHS’ Office for Civil Rights Settles Ransomware Investigation with Health Plan, 2026 -- HHS’ Office for Civil Rights Settles Ransomware Investigation
- United States Department of Health and Human Services, HHS Office for Civil Rights Reaches Settlement with Azul Vision, Inc. Over HIPAA Access Investigation, 2026 -- HHS Office for Civil Rights Reaches Settlement
- ADA News, Nevada health system to pay $75,000 to settle potential HIPAA violation, 2021 -- Nevada health system to pay $75,000 to settle potential HIPAA violation
- ADA News — New York health insurer pays $5.1M to settle potential HIPAA violations
- HHS’ Office for Civil Rights Settles HIPAA Investigation of Ambry Genetics Phishing Attack Affecting 225,000 Individuals | HHS.gov
- Summary of the HIPAA Security Rule | HHS.gov
- Resolution Agreements | HHS.gov
Based on findings from:
HHS’ Office for Civil Rights Settles HIPAA Investigation of Ambry Genetics Phishing Attack Affecting 225,000 Individuals
Office for Civil Rights (OCR). United States Department Of Health And Human Services, 2026.
https://www.hhs.gov/press-room/hhs-office-civil-rights-settles-hipaa-investigation-ambry-genetics-phishing-attack-affecting-225000-individuals.html
This content is an AI-generated, fully rewritten summary based on a published scholarly article. It does not reproduce the original text and is not a substitute for the original publication. Readers are encouraged to consult the source for full context, data, and methodology.